Microsoft warns of TerminalFix attacks deploying reverse tunnels

2026-08-31T19:23:19Z0973450f4b829f091eeb9757d4da3a7128a6d50335e098c9889609f9e98d17d5
Chinese Fire AntCisco IOS XRClickFixCloudflareExchange Online outageGRE tunnelMicrosoft DefenderPowerShellRhysidaTerminalFixWindows Terminalbrowser extensionscredential theftcryptocurrency theftdata breachdata exfiltrationfake-CAPTCHAinfostealerransomwarereverse-tunnelrouter compromisesession hijackingsocial-engineering

What happened

BleepingComputer security news digest covering ClickFix/TerminalFix social engineering that abuses fake Cloudflare CAPTCHA prompts to execute PowerShell, Chinese Fire Ant compromise of Cisco routers using covert GRE tunnels, ransomware and data-theft incidents, infostealer theft of AI service sessions, malicious browser extensions, and other security and service-impacting events. The most immediately actionable threats are TerminalFix command execution, router persistence/tunneling, credential and session theft, and ransomware-related data exfiltration.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0973450f4b829f091eeb9757d4da3a7128a6d50335e098c9889609f9e98d17d5
Enrichment time
2026-08-31T19:23:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.